LOCAL PROVENANCE INSPECTION

See what a file can prove about its origin

Inspect C2PA, metadata and provider signals locally. Nothing is uploaded.

PROVENANCE INSPECTORLOCAL ONLY
INPUT / FILE

Drop a file for local inspection

PDF · DOCX · XLSX · PPTX · images · text · LOCAL ONLY

LOCAL PROCESSINGInspection on your device
OPEN SOURCEAuditable code and standards
NO UPLOADSFiles stay local
REPRODUCIBLEToolchain in every report

Live example report

A public, reproducible C2PA test fixture. No fabricated product-demo values.

PUBLIC TEST FIXTURE / C2PALive example reportSIGNATURE VALID
signed.jpgC2PA public testfiles · JPEG · 140,297 bytes
SHA-256
75a8da33f6ea…4230ce864
STANDARD
C2PA 2.2
MANIFEST
DETECTED
SIGNATURE
VALID

Signature technically validProves integrity of the signed claims, not their truth.

OUR PRINCIPLE

Evidence, not guessing

AI detectors estimate probabilities. Provenance Lens reports only technical signals that can be checked, and says plainly when no check is possible.

PROBABILITYScore?Estimate without verifiable evidence
TECHNICAL EVIDENCEC2PA signature validReproducible and documented
01

What we report

Signed C2PA manifests, claim generators, signature validity, metadata fields, hidden Unicode characters and documented provider marks.

View check modules
02

What we never do

Assign a probability to authorship, call text "human-written", or claim a detection capability that no public mechanism supports.

03

How to verify us

Every check names the library and version that performed it. The scanner is open source. Run it yourself, offline.

Source on GitHub

CHECK MODULES

What Provenance Lens checks

Every module checks one clearly defined and documented provenance signal.

All check modules
● Check available● Not publicly checkable
Check available

C2PA Content Credentials

C2PA 2.2

Signed C2PA manifests, claim generators and signature validation results.

Check available

Embedded metadata

XMP / EXIF / IPTC

Embedded metadata fields, including generator and software fields.

Check available

Unicode anomalies

Unicode

Zero-width characters, bidi controls and related Unicode anomalies.

Not checkable

Anthropic text watermark

Provider-specific

No public detection mechanism is currently documented.

Check available

Anthropic image C2PA

C2PA 2.2

A matching provider claim in a C2PA manifest where present.

How it works

Four traceable steps. Every report records its method and limit.

  1. 01FileBytes are read locally.
  2. 02Local inspectionModules inspect their documented signals.
  3. 03VerificationSignatures and evidence receive distinct statuses.
  4. 04ReportSHA-256, toolchain and limits are recorded.

Provider ecosystem

Provider signals are documented, not assumed. A listed name does not mean a public detection mechanism exists.

OPEN SOURCE · CLI

For developers

Install the local scanner. It runs offline, reads the same signals as the hosted version, and emits the same JSON report schema.

  • Apache-2.0
  • Offline
  • JSON

v0.1.0 · Actively developed

InstallScan fileOutput
pip install provenance-lens
provenance-lens scan ./image.jpg --json
Result · JSON
{
  "schemaVersion": "1.0.0",
  "overallStatus": "VALID",
  "signalsFound": 2,
  "mode": "local"
}

Reproduce the report, not just the verdict

Scanner version, libraries, report schema and source remain visible so a finding can be reproduced independently.

SCANNER
provenance-lens 0.1.0
C2PA
c2pa-web 0.12.4
METADATA
exifr 7.1.3
SCHEMA
report-schema 1.0.0

Learn the standards behind the report

FOR WHOM

Use cases

Check and document provenance signals where traceable decisions matter.

MEDIA

Newsrooms

Check the provenance chain of a submitted image before publication.

  1. Receive file
  2. Check signals
  3. Document finding

Traceable editorial decision

View workflow
LAW & GOVERNANCE

Publishers and compliance

Record what was verifiable about an asset, and when.

  1. Record setup
  2. Archive report
  3. Support audit

Versioned evidence for internal review

View workflow
SOFTWARE

Engineering

Run provenance checks in CI and fail a build on an invalid manifest.

  1. Run CLI
  2. Parse JSON
  3. Control build

Automatable rules for invalid manifests

View workflow
RESEARCH

Researchers

Reproducible, versioned reports with the toolchain recorded in every output.

  1. Pin toolchain
  2. Record version
  3. Share result

Comparable checks across time and systems

View workflow

TRANSPARENTLY FUNDED

Free to check. Free to reuse.

Browser checks and the local scanner remain available without an account, upload limit or hidden paywall.

Apache-2.0 · Open Source
IN THE BROWSER0 €

Web-Scanner

  • Local in the browser
  • No uploads
  • No account
  • No limits
Scan a file
LOCAL & AUTOMATED0 €

Open-source scanner

  • Complete check modules
  • CLI & JSON output
  • Works offline
  • Custom integrations
Install scanner
VOLUNTARY

Support the project

Help us develop modules, documentation and open standards independently.

Support the project
No hidden costs.

All current core functions are publicly documented and available under an open licence.

Funding & transparency

FAQ

Can this tell me if text was written by AI?

No. No tool can do that reliably, and this one does not try. It reports whether a documented provenance signal is present. For most text, no such signal is publicly checkable today.

What does it mean if nothing is detected?

That the signals we checked were not found. It does not mean the content is human-written. It may mean the file never carried a signal, the signal was stripped by editing or re-encoding, or no public method exists to check it.

Are my files uploaded?

No. The check runs entirely in your browser. Your file is never sent to our servers, so we never receive it, never store it and never see it. Open your browser's network tab during a scan and you can confirm this yourself.

Is it free?

Yes, and there is no daily limit. Scanning costs us nothing, because it happens on your machine. The local command-line scanner is open source and free as well.

LOCAL ONLY / EVIDENCE FIRST

Inspect a file. Know what can actually be proven.

Scan a file